- Refactor WorkspacePolicy to use pivot role instead of workspace.user_id - Add manageBilling policy (owner only) to BillingController - Fix ApiKeyController authorization (view → manageTeam for store/destroy) - Fix WorkspaceInviteController using workspace.user_id for owner checks - Fix WorkspaceController settings is_owner using workspace.user_id - Create PostAction enum for UpdatePost/PostController action strings - Create ApiToken\Status enum - Add User::SUBSCRIPTION_NAME constant, replace all hardcoded 'default' - Convert wantsEmailFor to accept NotificationType enum - Convert all $data[] to data_get() across publishers, controllers, jobs - Fix SocialLoginController callback missing try/catch - Fix SocialController::toggleActive missing workspace null check - Fix UpdatePost NPE on meta merge when postPlatform not found - Remove HTML5 required attributes from form inputs - Convert function declarations to arrow functions in Vue components - Replace hardcoded URLs with Wayfinder route helpers - Replace new Date() with dayjs - Add 16 new test files covering policies, authorization, publishing
133 lines
4.4 KiB
PHP
133 lines
4.4 KiB
PHP
<?php
|
|
|
|
declare(strict_types=1);
|
|
|
|
use App\Enums\User\Setup;
|
|
use App\Enums\UserWorkspace\Role;
|
|
use App\Models\User;
|
|
use App\Models\Workspace;
|
|
|
|
beforeEach(function () {
|
|
$this->user = User::factory()->create(['setup' => Setup::Completed]);
|
|
$this->workspace = Workspace::factory()->create(['user_id' => $this->user->id]);
|
|
$this->workspace->members()->attach($this->user->id, ['role' => Role::Owner->value]);
|
|
$this->user->update(['current_workspace_id' => $this->workspace->id]);
|
|
});
|
|
|
|
// Subscribe tests
|
|
test('subscribe requires authentication', function () {
|
|
$response = $this->get(route('app.subscribe'));
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
test('subscribe shows subscription page', function () {
|
|
$response = $this->actingAs($this->user)->get(route('app.subscribe'));
|
|
|
|
$response->assertOk();
|
|
$response->assertInertia(fn ($page) => $page
|
|
->component('billing/Subscribe', false)
|
|
->has('trialDays')
|
|
);
|
|
});
|
|
|
|
// Index tests
|
|
test('billing index requires authentication', function () {
|
|
$response = $this->get(route('app.billing.index'));
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
test('billing index shows billing dashboard', function () {
|
|
$response = $this->actingAs($this->user)->get(route('app.billing.index'));
|
|
|
|
$response->assertOk();
|
|
$response->assertInertia(fn ($page) => $page
|
|
->component('billing/Index', false)
|
|
->has('hasSubscription')
|
|
->has('workspacesCount')
|
|
);
|
|
});
|
|
|
|
// Processing tests
|
|
test('billing processing requires authentication', function () {
|
|
$response = $this->get(route('app.billing.processing'));
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
test('billing processing shows processing page', function () {
|
|
$response = $this->actingAs($this->user)->get(route('app.billing.processing'));
|
|
|
|
$response->assertOk();
|
|
$response->assertInertia(fn ($page) => $page
|
|
->component('billing/Processing', false)
|
|
->has('userId')
|
|
->has('status')
|
|
);
|
|
});
|
|
|
|
test('billing processing accepts status parameter', function () {
|
|
$response = $this->actingAs($this->user)->get(route('app.billing.processing', ['status' => 'success']));
|
|
|
|
$response->assertOk();
|
|
$response->assertInertia(fn ($page) => $page
|
|
->where('status', 'success')
|
|
);
|
|
});
|
|
|
|
test('billing processing validates status parameter', function () {
|
|
$response = $this->actingAs($this->user)->get(route('app.billing.processing', ['status' => 'invalid']));
|
|
|
|
$response->assertOk();
|
|
$response->assertInertia(fn ($page) => $page
|
|
->where('status', 'processing')
|
|
);
|
|
});
|
|
|
|
// Checkout tests
|
|
test('checkout requires authentication', function () {
|
|
$response = $this->post(route('app.billing.checkout'));
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
// Portal tests
|
|
test('portal requires authentication', function () {
|
|
$response = $this->get(route('app.billing.portal'));
|
|
|
|
$response->assertRedirect(route('login'));
|
|
});
|
|
|
|
// Authorization tests
|
|
test('admin cannot access subscribe page', function () {
|
|
$admin = User::factory()->create(['setup' => Setup::Completed]);
|
|
$this->workspace->members()->attach($admin->id, ['role' => Role::Admin->value]);
|
|
$admin->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
$this->actingAs($admin)->get(route('app.subscribe'))->assertForbidden();
|
|
});
|
|
|
|
test('member cannot access subscribe page', function () {
|
|
$member = User::factory()->create(['setup' => Setup::Completed]);
|
|
$this->workspace->members()->attach($member->id, ['role' => Role::Member->value]);
|
|
$member->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
$this->actingAs($member)->get(route('app.subscribe'))->assertForbidden();
|
|
});
|
|
|
|
test('admin cannot access billing index', function () {
|
|
$admin = User::factory()->create(['setup' => Setup::Completed]);
|
|
$this->workspace->members()->attach($admin->id, ['role' => Role::Admin->value]);
|
|
$admin->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
$this->actingAs($admin)->get(route('app.billing.index'))->assertForbidden();
|
|
});
|
|
|
|
test('member cannot access billing index', function () {
|
|
$member = User::factory()->create(['setup' => Setup::Completed]);
|
|
$this->workspace->members()->attach($member->id, ['role' => Role::Member->value]);
|
|
$member->update(['current_workspace_id' => $this->workspace->id]);
|
|
|
|
$this->actingAs($member)->get(route('app.billing.index'))->assertForbidden();
|
|
});
|